Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us...

25
Elastic Search Gain Insight Into Your Enterprise

Transcript of Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us...

Page 1: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Elastic Search

Gain Insight Into Your Enterprise

Page 2: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

About us

University of Wisconsin – Milwaukee

University IT Services

• Chris Spadanuda – Associate Director Enterprise Services

• Ben Seefeldt – Lead Administrator IT Architecture and Infrastructure

• John Goodman – Manager, Identity and Access Management

Page 3: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

About UWM Enterprise Services

• Identity and Access Management

• Systems Support

• Business Applications

Page 4: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

UW Digital ID

UWM ePantherID

Page 5: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate
Page 6: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Enterprise Services - Goals

• Manage demand (MFA, Unified Communications, Storage, etc.)

• Modernize IAM infrastructure

• Update and refresh Data Center infrastructure

• Transition to cloud services – AWS, Azure

• Continue to increase compliance and security

Page 7: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

More data = More insight = More action• Early efforts

– Syslog Server, Splunk, AD Audit

• Information we wanted and problems to solve– Patch levels– Phishing mitigation– Identity login locations– Service performance– What applications and users are using our services– Service dependencies– Service utilization– Audit response and security (long term and short term)

Page 8: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

The Elastic Stack

Page 9: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Logstash

• Inputs

• Filters

• Outputs

Page 10: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Elasticsearch

• Indices

• Index templates

Page 11: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Ingestion

• Pipelines

• Data enrichment

Page 12: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Kibana

• Fields

• Index Patterns

Page 13: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Architecture

Page 14: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Architecture

Page 15: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Fields

• Timestamp

• Agent

• Client IP

• Geolocation

• Server IP

• Http_status

• Request uri

Page 16: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Data Types

• String

• Numeric

• Date

• Boolean

• Binary

• Array

• Objects

Page 17: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Aggregations

• Building blocks towards more complex data summaries

• Buckets: Match relevant data based on defined criteria

• Metric: Track and compute information from a set of documents

Page 18: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Visualizations

• Based upon queries

• Dashboards

• Bar graphs

• Pie charts

• Tables

• Coordinate maps

Page 19: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Identifying Data Sources

• Authentication attempts (Success / Failure)

• Load balancer performance

• Webpage load times

• Error status

• Sourcing service usage

• Identify client software connections (OS / Browser type)

Page 20: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Putting Data Into Action

• Office 365 authentication attempts

• Geolocation of authentication attempts

• Correlating similar authentication attempts

• Identifying user impact

Page 21: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Compromised Accounts

Page 22: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Compromised Accounts

Page 23: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Compromised Accounts

Page 24: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Compromised Accounts

Page 25: Elastic Search - itlc.it.wisc.edu · Elastic Search Gain Insight Into Your Enterprise. About us University of Wisconsin –Milwaukee University IT Services •Chris Spadanuda –Associate

Demo